First published: Thu May 20 2021(Updated: )
SQL injection vulnerability in the KonaWiki2 versions prior to 2.2.4 allows remote attackers to execute arbitrary SQL commands and to obtain/alter the information stored in the database via unspecified vectors.
Credit: vultures@jpcert.or.jp
Affected Software | Affected Version | How to fix |
---|---|---|
Kujirahand Konawiki | <2.2.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-20720 is a SQL injection vulnerability in the KonaWiki2 versions prior to 2.2.4.
CVE-2021-20720 allows remote attackers to execute arbitrary SQL commands and to obtain/alter the information stored in the database.
The severity of CVE-2021-20720 is critical with a CVSS score of 9.8.
To fix CVE-2021-20720, you should update KonaWiki2 to version 2.2.4 or later.
You can find more information about CVE-2021-20720 at the following references: [Link 1](https://jvn.jp/en/jp/JVN34232719/index.html), [Link 2](https://kujirahand.com/konawiki/)